290 points•ibobev•2 days ago•92 comments•

92 comments

barake2 days ago
This is how Lightstream Studio has provided stream overlay for consoles[1]. Some years ago Microsoft added them as an official destination using a better protocol and dropped the need for MITM hackery.

I used to work in this space and Lightstream was always doing interesting things, even if they never seemed to find PMF.

1: https://support.golightstream.com/hc/en-us/articles/38643168...

jbs7892 days ago
PMF… I love how we’ve invented a term which means “customers”. I know it’s not the point of your comment but the acronym in place of a common word will be tougher for folks to follow.
jonchurch_2 days ago
In case anyone gets to learn this today…

You can have customers without product market fit.

A product that hasnt found PMF could be a solution looking for a problem, or it might solve a true problem but that problem isn't important, durable, or (crucially) common enough to sustain a business.

So OP was saying that Lightstream Studios made some great stuff, but that ultimately the problem they were solving wasnt durable or widespread enough for the market to sustain the business they had built.

Background on Lighstream Studios is they did a streamer setup in the cloud, so you didnt have to run OBS locally. A lot of people seemed to want that at the time, especially console gamers, but the market changed around them. Consoles are way better at streaming without any other stuff now, and PC gamers largely settled on running OBS (for free) on their own existing hardware. They had like 17k paying customers at one point, so customers wasnt the smoking gun here.

Modified30192 days ago
Thanks, I had no idea what it meant (presumably “product market fit”). “Pull My Finger” was going to be my best guess.
nemothekid1 day ago
There are plenty of businesses with customers that don’t sell products. The PMF distinction is useful because many startups are actually specialized consultants/agencies, not products.

There are plenty of companies (successful ones) that I’d argue don’t have PMF, but have plenty of customers (ex Palantir)

londons_explore2 days ago
Kinda sad that it's 2026 and this data still goes over the internet unencrypted...

RTMP and all the video and audio protocols behind it aren't trivial either - I bet there are hundreds of exploits waiting to be found that any three letter agency sitting on the internet can use to take over your PS5 and all credentials stored within too...

rezonant2 days ago
Well, the server just responds with acknowledgement information, the client is doing most of the work and most of the complex parts of RTMP are hand waved and faked by both the client and the server because no one cares about how Flash used to work.

So somewhat unlikely to be able to exploit it but have at it hass.

I'd imagine it'd be easier to exploit the server side, actually.

londons_explore2 days ago
Yeah, but the server is most likely running the whole thing in a docker container with no permissions to do anything. Big companies security teams tend to require that when opening non-trivial third party code up to the internet.

The client on the other hand I would guess is running it's code as root, or at least something with full GPU access.

opello2 days ago
Wouldn't this require a man-in-the-middle since the PS5 is transmitting data to a specific server, YouTube or Twitch in the article?

There are extensions to RTMP to use encryption or even just TLS. But do you mean that the risk of fragments of audio and video bitstreams going out unprotected presents a remote code execution risk? That seems less a problem of vulnerability and more one of privacy.

someonebaggy2 days ago
I think everyone is just hardcoding a template RTMP conversation and not implementing it beyond looking for certain markers.
dylanger2 days ago
It is pretty wild that RTMP without any TLS is a thing, anyone in the chain, ISPs etc could just sit there and log all RTMP traffic and tap the stream at any time.
londons_explore2 days ago
Would be pretty funny for an ISP to MITM all streams and put a "internet provided by Verizon" watermark in the corner of all video...
hjkloinxbdj1 day ago
This is not correct, twitch (AWS IVS) supports rtmps.

The OP didn’t intercept rtmp url, they intercepted the discovery endpoint.

mixdup2 days ago
Maybe I'm missing something but there seems to be a gap between "figure out the REAL hostname" and "we no longer have to worry about the stream never showing up on YouTube"
Sebb7672 days ago
The live-video.net domain belongs to Twitch. So, from what I can gather, apparently the OP switched back to Twitch streaming and the last-hop RTMP server does not use certificates.
fnctrev2 days ago
twitch doesnt actually require tls. it uses plain rtmp over port 1935 and rtmps over port 443.
Aissen2 days ago
Me too. YouTube was given up, and what the op did was to use Twitch streaming and redirect it before the forward to a TLS-verifed server, bypassing verification:

> redirects the actual stream to the Mac without any certificate issues.

Muromec2 days ago
Don't mind me, I'm just sitting here with my HDMI-RX port on rk3588 being happy that is works and I didn't brick the board when doing uboot update to uncurse it.
concerneddork2 days ago
Lucy, esplain please.
kotaKat2 days ago
rockchip something-or-other that's on the KiwiPi 5B. iirc it can strip hdcp and all that jazz, too? one of the ports is labeled "HDMI RX" for input.

https://kiwipi.com/blog/rk3588-hdmi-in-test/

jprjr_2 days ago
Feel like there's a few parts missing that I'm not getting.

The author mentions that the PS5 uses RTMPS to push video up to twitch - but suddenly it just uses plain RTMP?

sleepybrett2 days ago
because he switched to it's youtube integration which doesn't support RTMPS...
mintplant2 days ago
But that integration kept timing out, so the author switched back to Twitch and somehow found a plain-RTMP endpoint that time. I'm also confused.

Read the full thread on Hacker News →

Related stories